﻿using System;
using System.IO;
using System.Reflection;
using System.Web;
using AnyOffice.Components;
using log4net;
namespace AnyOffice.general.file_folder
{
    public partial class show_photo : ModulePage
    {
        private static ILog log = LogManager.GetLogger(MethodBase.GetCurrentMethod().DeclaringType);
        protected void Page_Load(object sender, EventArgs e)
        {

            try
            {
                Response.Buffer = true;
                Response.Clear();
                string str = (Request.QueryString["filename"] != null) ? Request.QueryString["filename"].ToString() : "";
                str = str.Replace("../", "");
                string str2 = "/attachment/file_folder/" + HttpContext.Current.User.Identity.Name;
                FileInfo info = new FileInfo(Server.MapPath(str2 + str));
                if (info.Exists)
                {
                    Response.ContentType = "image/jpeg";
                    Response.WriteFile(info.FullName);
                }
            }
            catch (Exception exception)
            {
                if (log.IsErrorEnabled)
                {
                    log.Error("", exception);
                }
            }
        }
    }
}
